QID 375790

Date Published: 2021-08-05

QID 375790: MongoDB Command Execution Vulnerability (SERVER-50605)

MongoDB is an open-source document database, and NoSQL database.

CVE-2021-20333: Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split.

Affected Versions:
MongoDB Server v3.6 affects versions prior to 3.6.20.
MongoDB Server v4.0 affects versions prior to 4.0.21.
MongoDB Server v4.2 affects versions prior to 4.2.10

QID Detection Logic:(Authenticated)
This QID checks for vulnerable version of MongoDB installed on the target.

Successful exploitation may result in artificial log entries being generated or for log entries to be split.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customer are advised to update MongoDb to the latest versions.
    For more information visit MongoDB SERVER-50605
    Vendor References

    CVEs related to QID 375790

    Software Advisories
    Advisory ID Software Component Link
    SERVER-50605 URL Logo jira.mongodb.org/browse/SERVER-50605